🎉Celebrating Lumi Finance Audit Report successfully passed and Lumiterra Mainnet beta#1
Lumi Finance will roll out a patch in 24 hours
- Increasing the APY of adding LUAUSD liquidity
- LUAOP airdrop for all staked LUA users
- Optimize staking-only(without adding liquidity) APY
We'll deploy the contract on ETH later this month, all the assets you've transferred to that network will be on your wallet
No one owns your private key, assets are safe
Thank you
📦 Genesis Mystery Box 101
🎲 Roll Dice in telegram, completely fair
💁Detail:
https://t.co/yGLz9OujXa
❤️Like + RT each countdown tweet
💬Comment "Go Go Go, Lumiterra" under each tweet
💎3 lucky winner | 150 $USDT on the launch day
🔐 Dive into @R4ZN1V's article for key insights on protecting your web3 wallet from drainers. Practical, informative, and essential for digital asset security. 🛡️💡
I’ve spent my career tracking malware, first in cyberintelligence and now at @blockaid_. I’ll be sharing a series of Malicious dApp 101 posts for non-technical users to get familiar with key web3 security issues, starting today with Wallet Drainers.
⛔𝐌𝐞𝐦𝐞𝐜𝐨𝐢𝐧 𝐒𝐜𝐚𝐦𝐬⛔
This Memecoin Scam ad has drained 16.82 ETH so far.... With many red flags, users still fall victim to the scam ads from twitter.... Lets take a deeper look⤵️⤵️⤵️
Whenever there is something popular in web3, scammers always like to target that project/business/claim/aidrop/etc. for phishing, drainers, and social engineer scams... As we can see in the one of many scam ads above, a scammer got control of a blue check account, posted a scam link to a drainer website, turned off comments, and botted engagement. These are always red flag signs to look for in scam ads.. Sadly this ad and 3 other scam ads all focused on @9gagceo 's memecoin, I have tracked, have led to 16+ ETH being drained thus far...
The websites are very basic and minimalistic, as they tell you that you can claim $MEME and you just have to connect your wallet and sign a signature to "claim"...
Meanwhile what this is actually doing is giving an 'approve all' signature to drain everything out of your wallet, @wallet_guard plug-in of course shows you this and helps prevent everyone from accessing the drainer site to begin with and then also shows that signing this signature with take everything out of your wallet
These scam ads are rampant, as almost every ad is a scam, as I did further research in this thread:
https://t.co/chE59HOFry
Always be vigilant when clicking on links, and visiting sites and double check everything you can see, and use @wallet_guard to protect you from things you can't see!! This scam ad technique changes frequently but the premise of it is still there, to drain your assets..
I hope this helps bring awareness to this matter and @Support and @Safety can implement safe guards in place like Wallet Guard API into the ads to prevent these scam websites from even being allowed on the platform!
Stay Vigilant & Stay Safe
🚨SlowMist Security Alert🚨
Unibot @TeamUnibot has been exploited, and due to the lack of necessary parameter checks, the exploiter can transfer tokens for which users have approved the Unibot contract.
Please revoke approval of 0x126c9FbaB3A2FCA24eDfd17322E71a5e36E91865 ASAP!
Just on October 25, 2023 alone another ~$4.4M was drained from 25+ victims as a result of the LastPass hack.
Cannot stress this enough, if you believe you may have ever stored your seed phrase or keys in LastPass migrate your crypto assets immediately.
⚠️ SlowMist Security Alert!
Recently, there have been malicious scripts targeting https://t.co/GyBaNhfUIv (ft). This is a JavaScript code, where scammers lure potential victims into adding it as a bookmark.
When users access the ft site and execute this bookmark, the malicious script attempts to steal their passwords (specifically, ft's 2FA as shown in Figure 1) and tokens associated with the embedded wallet, Privy, used by ft (as shown in Figure 2). This means that the user's ft account and related funds are at risk of theft.
This is not a new technique. Such malicious bookmark has been frequently used in schemes targeting Discord accounts. This serves as a reminder that similar tactics can be used elsewhere.
As always, stay vigilant!
Check out @0xBundleBear to get a comprehensive view of the current on-chain data for the ERC4337 protocol.
Definitely worth a look! 👀 🔗 https://t.co/ECpZ7sEzEl #ERC4337
@0xQuit shared insights on security risks and protective measures related to Friendtech assets. It's recommended to check it out and ensure the safety of your assets.
https://t.co/bpNmddyFh4
@0xQuit shared insights on security risks and protective measures related to Friendtech assets. It's recommended to check it out and ensure the safety of your assets.
https://t.co/bpNmddyFh4
Friendtech user @digging4doge just got drained to the tune of ~60 eth worth of keys.
About an hour ago, he received a text informing him that a number change had been requested for his account.
He had two hours to respond or the request would be auto approved. This was, of course, not actually from friendtech.
It was from a scammer looking to phish his login code, the only thing required to log in to an sms backed friendtech account on a new browser.
In a panic, Poop provided the code.
Minutes later, the scammer started selling his keys. Poop's 60 eth was wiped out, hurting everybody who held his keys and everybody whose keys he held.
The scammer even left some gifts from Poop in everybody's rooms before dumping their keys.
Do NOT use SMS to sign up for friendtech. Even if you don't fall for a social engineering scam like this one, you're one sim swap away from losing your portfolio.
Use an email, preferably a fresh one. Lock the email down with a Yubikey or Authenticator 2fa. Do not have a backup email associated with the email.
It does not take long and could easily save your ass in the future.
We're already starting to see others dumping keys because of "friendtech security flaws". If you set up correctly, you do not need to worry.
But you need to protect your login. And perhaps it's worth investigating how others have protected theirs before buying their keys. I know mine are safe.
Stay safe out there fam.
It's hard to believe 6 months have already passed since EntryPoint.sol was deployed to mainnet
One of our recent grantees @SixdegreeLab, has released a report that covers the rapidly growing adoption for ERC-4337, made possible by all the great teams building on it 🚀
This year, over 𝟴𝟬𝟬,𝟬𝟬𝟬 ERC4337 smart accounts have been deployed, with 50% of them being deployed in the past month
ERC4337 wallets is future of onchain UX 🧑💻✨
I wrote a report summarizing key stats on
- Popular ERC4337 usecases
- Most active L2s for ERC4337
and more!
As they build out ERC-4337, the core dev team has to deeply analyze some of the fundamental concepts surrounding account abstraction.
@drortirosh shares his insights on the inherent properties these accounts must maintain to remain truly decentralized
https://t.co/LjHXvU9afi
Hey @punk6529 dishing out #crypto safety insights 🚀!
Sad to hear about folks getting ensnared by phishing traps 😢.
🌟 Have you thought about seedless options? Try Sodium Wallet!
Boost your #web3 security with these savvy tips:
1/ On The State of Your NFT Security
A few comments on my casual security survey here on twitter.
Of course, there is huge selection bias in terms of who answered, but it does not matter - it serves its purpose anyway
Exciting growth in ERC-4337 Smart Accounts this August! 🚀
Dive deeper with @0xKofi's insights on Dune: https://t.co/0vwppDFmYG.
Thanks for being on this journey with us! 😄
#MPC#ZK#ERC4337
Over the past four months $13.3M+ has been stolen as a result of 54 SIM swaps targeting people in the crypto space.
When an account is compromised scammers attempt to create a sense of urgency with a fake claim to drain your assets.
Never use SMS 2FA and instead use an authenticator app or security key to secure accounts.
Your wallet isn't just tokens. It's reputation & connections. 🌍✨ Review & revoke unused contracts and consider keyless options like @sodiums_org. 🙌
BTW, check out @SlowMist_Team's https://t.co/SFrBVnkJSw for a safer #Web3 journey! 📖🛡️
#MPCwallet
How I Lost My Wallet, My Tokens, and My Onchain Identity to a Hacker
Yesterday, my wallet's private key was compromised, and I lost all access to my wallet to an unknown hacker.
What hurts more is that I lose all the onchain activity and reputation I've built with this wallet over the years.
I must have signed a malicious contract that somehow gave the exploiter access to my private key.
The attacker transferred 0.089 ETH from my Arbitrum account to his wallet at 0xC3c4649b2b3e8e057188bbC5D3DFBC7432737602
https://t.co/Fa4M9nPbuO
Then, when I tried to transfer my remaining $DAI tokens to another wallet I own, all the transactions were automatically redirected to another wallet (0x356575bB05A3C335a254fACa5366f7C996C97fC4).
https://t.co/qBP3R0gSam
Someone at @peckshield's TG brought to my notice that this @binance deposit address 0x03E8729D4B815c575E0654f794293F04F12f1DA7 belongs to the exploiter.
They have been exploiting wallets with smaller balances thinking it would go unnoticed. But this impunity, over time, can make them exploit many more accounts over time.
The exploiter proceeded to transfer tokens to Tornado Cash to clean all trails.
My tokens on Arbitrum, Binance & zkEVM were drained completely.
I lost ~$300 and the ability to use my wallet for further use.
I lose the ability to vote on governance forums, withdraw my stakes, verify my onchain identity, and worst of all, the research I've been posting on Mirror for 2 years now.
These are the wallets that belong to the hacker:
-- 0x356575bB05A3C335a254fACa5366f7C996C97fC4
-- 0xC3c4649b2b3e8e057188bbC5D3DFBC7432737602
-- (Binance deposit address) 0x03E8729D4B815c575E0654f794293F04F12f1DA7
Can @binance@cz_binance help with identifying the exploiter in this case? Any help would be appreciated.
The mistake I clearly made was that I have been using the wallet with a private key on my Metamask for years which I had not noticed.
This made my wallet and onchain activity riskier than others.
Also, metamask does not have the option to check & revoke approvals, if any.
What I tried to do is import my wallet to @Rabby_io and revoke all access that I had granted earlier. It is probably the best Ethereum wallet out there.
But since any ETH I deposit into my compromised wallet gets withdrawn automatically to another wallet owned by the hacker, it is now impossible to revoke any contracts at the moment.
Any help in identifying the hacker would be appreciated. @zachxbt@peckshield's Telegram group chat members were really helpful in identifying that my private key was compromised and suggesting the next steps I should follow to protect my existing tokens. Highly recommend you join the group.